PayPal Starts Bug Bounty Program
Trailrunner7 writes "PayPal is the latest company to join the ranks of software vendors and Web properties that offer bounties to security researchers who privately disclose new bugs to them. The company isn't saying how much it will pay for each bug, just that its security team will determine the severity of each flaw as well as the ultimate payout. PayPal's decision to offer financial incentives to researchers follows the establishment of similar programs by companies including Google, Mozilla, Facebook, Barracuda and others. Google's bug bounty program may be the most well-known and comprehensive, as it includes bugs not just in its software products such as Chrome, but also its Web properties. The company has paid out more than $400,000 in rewards to researchers since the program began and researchers who consistently find bugs in Google's products can make a nice side income off the program."
PayPal has been around for more than a decade. They handle a lot of other peoples' money. And they still have bugs?!?
People who know this and continue to use PayPal... well... wow.
I don't respond to AC's.
Oh my gods.. I can't breathe!
What the hell is this? Since when has Paypal been concerned about quality of service to ANYONE?
Every problem I have ever reported has resulted in a metaphorical slap in the face, tons of paperwork, or both. Everyone is guilty until proven innocent but the scammers who can easily sidestep anything they do and only the honest get punished. Why would this be different with bugs?
We reserve the right to determine how much we will pay you for benefiting PayPal under any and all circumstances....
I object to power without constructive purpose. --Spock
I believe freezing peoples funds because according to your heuristics their spending behaviour indicates that they're an outlier is a bug... oh wait, I think that's intentional... mark WONTFIX.
I'm going to get paid for finding bugs in Paypal??? I'm going to be RICH!!! RICH BEYOND MY WILDEST DREAMS!!!!!!!!!
"The Milliard Gargantubrain? A mere abacus - mention it not."
I just wonder if every one who made a sale and got a 25 pound coupon earlier this month will get a payout. I mean, come on... half a coupon gets munched by a system, people tell them about it, and they say... we've escalated this to this dep't and we might get back to you sometime if we find out what went wrong. Yeah, your coupon is lost and sorry for charging you real money. I'd class that as finding a but worthy of a payout under this programme.
No.. Rob Malda has just picked you for an anal sex romp. Enjoy it.
It's their Management. If they would fix that....
How much is that worth?
Life takes interesting turns, but the most interest is when you're off the beaten path.
The bounty will be paid in your paypal account (if you do not have one, you will have to create one), and then paypal will freeze your account without any explanation or appeal process :)
I apologize for the lack of a signature.
It is normal... I get 5 and 15 about equally.
Does this count as a bug? They send out customer surveys that actually are from them but look extremely fake and point to a domain other than their own, which violates every single internet standard and their own safety and security guidelines.
Oh and every time I go to their site, it attempts to launch the default media player plugin for whatever browser I'm using which gets blocked as a security threat by default in default configurations of IE8 and 9 and I think Firefox as well.
I've already got a team of Nigerians on it.
The problem is that most of the bugs are in the human end of the system, not in the software.
Technoli